quick-research

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from external research queries. Ingestion points: Output from the grep-api.js script in SKILL.md. Boundary markers: Absent; there are no instructions to the agent to treat external content as untrusted or to use delimiters. Capability inventory: The skill executes shell commands via node scripts. Sanitization: No evidence of output sanitization or filtering is provided.
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts for functionality. Evidence: Calls to auth.js and grep-api.js using a resolved scripts directory path in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 09:40 PM
Security Audit — agent-trust-hub — quick-research